Draft:Jonathan Bar Or


Jonathan Bar Or is an Israeli–American security researcher known for his work in vulnerability research, offensive security, and reverse engineering. He has been credited with the discovery of multiple security vulnerabilities (CVEs) affecting operating systems, bootloaders, mobile platforms, and widely deployed software components.

Career

Bar Or has worked as a security researcher in the technology industry, including as part of the Microsoft 365 Defender Research Team. His work focuses on identifying and analyzing vulnerabilities across platforms such as macOS, Linux, Android, ChromeOS, and embedded systems.[1]

His research has contributed to vulnerability disclosures affecting major vendors including Apple, Microsoft, Google, and network device manufacturers.

Research and vulnerability disclosures

Bar Or has been credited with discovering or co-discovering numerous vulnerabilities assigned Common Vulnerabilities and Exposures (CVE) identifiers.

macOS and Apple ecosystem

Bar Or was credited for discovering CVE-2021-30970, a vulnerability in macOS’s Transparency, Consent, and Control (TCC) framework that could allow unauthorized access to sensitive user data.[2]

He also reported CVE-2021-30892, a vulnerability affecting System Integrity Protection (SIP), which could allow attackers to bypass system protections.[3]

His research has also included vulnerabilities affecting macOS Gatekeeper, demonstrating methods of bypassing file quarantine and execution controls, as well as multiple sandbox escape techniques.

ChromeOS and browser security

Bar Or co-discovered a critical ChromeOS vulnerability involving remote memory corruption that could potentially lead to code execution. The vulnerability was disclosed in coordination with Google and subsequently patched.[4]

Linux and open-source software

Bar Or has contributed to vulnerability disclosures in Linux and related ecosystems, including memory corruption issues in widely used libraries such as ncurses.[5]

He has also participated in coordinated disclosure efforts through public security mailing lists such as oss-security.[6]

Android and telecommunications

Bar Or has identified high-severity vulnerabilities in Android applications and mobile ecosystems, including issues affecting applications with large user bases and telecommunications-related attack surfaces. His research demonstrated how flaws in mobile applications could expose sensitive user data or enable privilege escalation across devices.[7]

Network devices and routers

Bar Or has reported vulnerabilities in network infrastructure devices, including router firmware flaws that could lead to full system compromise or identity theft if exploited.[8]

Whisper Leak and LLM side-channel attacks

Bar Or co-authored research describing Whisper Leak, a side-channel attack against large language models (LLMs) that infers user prompt topics by analyzing encrypted network traffic patterns such as packet size and timing.[9]

The research demonstrated that attackers observing encrypted TLS traffic could classify sensitive topics in AI chatbot conversations despite encryption protections.[10]

The work received coverage in major media outlets. Forbes reported that the vulnerability could expose user interactions with AI systems and raised concerns about privacy risks in encrypted communications.[11]

Other platforms

Bar Or reported CVE-2022-2587, a memory corruption vulnerability in ChromeOS that could potentially allow remote code execution.[12]

His work spans additional domains including bootloaders, sandbox escapes, and cross-platform exploitation techniques.

Publications and speaking

Bar Or has contributed to the cybersecurity community through technical publications, vendor security research blogs, and academic work, including co-authoring research on LLM side-channel attacks.

He is also a public speaker and has presented at security conferences such as DEF CON, BlueHat, AVAR, and Nullcon, covering topics including macOS security, vulnerability research methodologies, and exploitation techniques.

Awards and recognition

Bar Or was awarded the Israel Defense Prize in 2014, one of Israel’s highest honors for contributions to national security.

See also

References

  1. ^ "Inside Microsoft Threat Intelligence: Where research powers resilience". Microsoft. Retrieved 2026-04-12.
  2. ^ "Microsoft security researchers found macOS exploit can alter protected user data". TechSpot. Retrieved 2026-04-12.
  3. ^ "Microsoft warns of nasty new macOS vulnerability". TechRadar. Retrieved 2026-04-12.
  4. ^ "Microsoft: How we unearthed a critical flaw in ChromeOS and how Google fixed it". ZDNet. Retrieved 2026-04-12.
  5. ^ "Debian LTS: ncurses security update". LinuxSecurity. Retrieved 2026-04-12.
  6. ^ "oss-security mailing list archive". Seclists. Retrieved 2026-04-12.
  7. ^ "Inside Microsoft Threat Intelligence: Where research powers resilience". Microsoft. Retrieved 2026-04-12.
  8. ^ "Inside Microsoft Threat Intelligence: Where research powers resilience". Microsoft. Retrieved 2026-04-12.
  9. ^ "Whisper Leak: A novel side-channel attack on remote language models". Microsoft Security Blog. Retrieved 2026-04-12.
  10. ^ "Whisper Leak: a side-channel attack on Large Language Models". arXiv. 2025.
  11. ^ "AI Chat Privacy At Risk—Microsoft Uncovers Whisper Leak Side Channel Attack". Forbes. Retrieved 2026-04-12.
  12. ^ "CVE-2022-2587". Wiz. Retrieved 2026-04-12.

References

Content Disclaimer

Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.

  1. The information displayed on this website is sourced in part or in whole from Wikipedia and has been adapted for the purpose of restating it. We strive to provide accurate and relevant information, however:
  2. There is no guarantee of absolute accuracy. Wikipedia is an open, collaborative project that can be edited by anyone, so information is subject to change.
  3. It is not intended to constitute professional advice. The content displayed is for informational and educational purposes only. For important decisions (e.g., medical, legal, or financial), please consult a professional.
  4. Content copyright. Wikipedia is licensed under the Creative Commons Attribution-ShareAlike License (CC BY-SA). This means that content may be reused with appropriate attribution and shared under a similar license.
  5. Responsible use. Any risk arising from the use of information from this website is entirely the responsibility of the user.